ShieldHub Sub-processors

Effective December 3, 2025

ShieldHub uses the third-party entities listed below (each, a “Sub-processor”) to process Customer Personal Data on behalf of ShieldHub users in accordance with agreements between ShieldHub and the Sub-processor. These agreements ensure that Sub-processors uphold ShieldHub’s commitments as set forth in ShieldHub’s Data Processing Policy.

Defined terms such as “Personal Data,” “Customer Personal Data,” “Sub-processor,” “Services,” or “End User Personal Data” have the same meaning as in ShieldHub’s Data Processing Addendum or applicable user agreements.

The list below identifies Sub-processors used for ShieldHub services and any related support or advisory functions. If a new Sub-processor is engaged for a beta or early access service, ShieldHub may provide notice through an alternative communication method. Personal Data processed by each Sub-processor is handled for the duration of the customer’s use of the applicable service(s) and retained according to the periods specified in the customer agreement and any related product documentation. Additional information about Sub-processor security measures can be found via the external links provided below.

Sub-Processor Applicable Cloud Products Nature and Purpose of Processing Categories of Personal Data Location of Processing Security Measures
Amazon Web Services, Inc. All ShieldHub portals and products Cloud hosting provider Customer Personal Data, created by customer or by Consumer Reporting Agency United States AWS Compliance Programs
ClearStar Consumer Reports Consumer Reporting Agency Customer Personal Data, created by customer or by Consumer Reporting Agency United States Security Assurance & Compliance
Microsoft Corporation Office 365, Cloud hosting, infrastructure-as-a-service, productivity services, email, file storage, authentication (Azure, Office 365). InfrastructureData storage, compute, database hosting, authentication, email, document management. Account data, operational data, limited customer support artifacts. United States Trust Center
Onfido, Inc (Entrust) ShieldHub Verified User Products; ID scanning, biometric matching, fraud detection. Identity verification and document authentication provider. ID images, biometric data (face match), metadata, verification results. United States Legal & Compliance
Freshworks Customer support ticketing, CRM, and communications platform (Freshdesk, Freshchat, etc.). Support case management, communication tracking, customer interaction data. Customer contact information, support content, logs. United States Trust Center
Atlassian Project management, issue tracking, documentation platform (Jira, Confluence). Internal operations, task management, workflow documentation. Internal operational data, documentation, workflow information that may reference customer data in limited cases. United States Trust Center
Stripe Payment processing, billing operations, subscription management. Payment card processing, invoicing, billing events, transaction history. Payment details, billing contact information, metadata related to transactions. United States Security at Stripe
Headway App Product Release Notes and Changes Release notes management No customer or personal data is processed. United States Security at Headway
Drata Continuous compliance automation platform. Security monitoring, evidence collection, vendor oversight workflows. No customer or personal data is processed. United States Trust Center